Data Breaches · Supply Chain

CrowdSec Leak Traced to Stale GitHub Access

CrowdSec said a former employee’s still-active GitHub token was used on May 22 to copy about 170 private repositories, and it traced the access back to the May TanStack npm supply-chain backdoor, CVE-2026-45321. The code surfaced on a forum on September 16, and CrowdSec disclosed the link on September 18.

TanStack’s malicious npm packages stole credentials from developer machines, and CrowdSec says the stolen GitHub token outlived the laptop compromise and the employee’s departure. Because the token was still valid, GitHub treated the copy-out as normal use; CrowdSec says its own infrastructure and databases were not accessed, and no code was changed.

The exposure sits in offboarding and token lifetime, not in CrowdSec’s servers. If a developer machine or former employee account still carries trusted GitHub access, private source can leave through that path even when the target company’s core systems show no breach.

2 sources · 14h ago

CVE-2026-45321

NVD KEV

Known exploited · CISA KEV

CVSS 9.6 CRITICAL: on 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. EPSS 2% (81st percentile).

CISA federal remediation date Jun 10 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: CrowdSec Leak Traced to Stale GitHub Access

More from today